Microsoft Posts Critical Security Fixes



By JESSICA MINTZ, AP Business Writer

Microsoft Corp. released four critical patches Tuesday to plug
security holes in several versions of its Windows operating system,
Internet Explorer Web browser and other programs.

The patches that carried Microsoft's highest security warning all are
to prevent malicious hackers from remotely taking control of computers
without permission.

Three of the patches aim to protect Windows users who unwittingly
expose their computers to attack by visiting Web pages infected with
malicious code, or look at similarly tainted e-mails with Outlook
Express or Windows Mail. A fourth patch prevents hackers from gaining
remote access to PCs by installing a specially crafted program.

Two of these critical updates fix holes in the company's newest
operating system, Windows Vista, which Microsoft has touted as the
most secure ever.

Vista went on sale to consumers at the end of January; in April,
Microsoft broke its once-monthly update schedule with an emergency fix
after Microsoft and security experts found that hackers were
exploiting a hole in the way Vista and other versions of Windows
handle animated cursor files.

Besides the critical fixes, Microsoft released a patch for its Visio
program for making diagrams and a vulnerability in Windows that could
allow unauthorized users to break into computers to steal passwords
and other user information.

Microsoft also released seven non-security, high-priority updates
Tuesday, including a monthly update to a tool that removes harmful
software from PCs.

On the Net:

http://www.microsoft.com/security

Copyright © 2007 The Associated Press.

NOTE: For more telecom/internet/networking/computer news from the
daily media, check out our feature 'Telecom Digest Extra' each day at
http://telecom-digest.org/td-extra/more-news.html . Hundreds of new
articles daily. And, discuss this and other topics in our forum at
http://telecom-digest.org/forum (or)
http://telecom-digest.org/chat/index.html

For more news and headlines, please go to:
http://telecom-digest.org/td-extra/AP.html

.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #242
    ... MICROSOFT VULNERABILITY SUMMARY ... PostNuke Blocks Module Directory Traversal Vulnerability ... Groove Networks Groove Virtual Office COM Object Security By... ... The Microsoft Windows IPV6 TCP/IP stack is prone to a "loopback" condition initiated by sending a TCP packet with the "SYN" flag set and the source address and port spoofed to equal the destination source and port. ...
    (Focus-Microsoft)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #49
    ... Subject: SecurityFocus Microsoft Newsletter #49 ... Microsoft Windows NNTP Denial of Service Vulnerability ... Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability ... Microsoft ISA Server H.323 Memory Leak Denial of Service... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #153
    ... MICROSOFT VULNERABILITY SUMMARY ... ZoneAlarm Random UDP Flood Denial Of Service Vulnerability ... FloosieTek FTGatePro Mail Server Path Disclosure Vulnerabili... ... Microsoft Windows NetBIOS Name Service Reply Information Lea... ...
    (Focus-Microsoft)

Loading